


Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)

Rust-based scanner for Grafana path traversal vulnerability (CVE-2021-43798). Checks hosts for the flaw and reads arbitrary files from affected…

This repository hosts PoC exploits for vulnerabilities I've discovered, provided for education and to highlight the importance of system security.

Materials for CVE-2024-30052.

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets,…

Log4Shell (CVE-2021-44228) docker lab

A cheatsheet for exploiting server-side SVG processors.

OD&H's scanner for CVE-2024-25600 vulnerability in the Bricks Builder WordPress plugin. For use in Try Hack Me (THM) environments.

The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

Hunt for and Exploit the libSSH Authentication Bypass (CVE-2018-10933)

🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

This repository hosts a multimodal web attack dataset (MWAD) to advance AI-driven threat detection research.

This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on…

CVE-2025-27480 exposes a buffer overflow in OpenSSH 8.9p1 via a malformed SSH_USERAUTH packet. Attackers can inject shellcode and gain SYSTEM-level…